NIS2 compliance for research institutions — abstract cybersecurity network visualization

Are You a Research Institution Under NIS2? The Annex II Scope Test That Catches Universities Off Guard

If your role includes NIS2 compliance for a European university or research institute, you have probably encountered the standard guidance: count your headcount, check whether research is your sector, and if you exceed 50 employees or €10 million in annual turnover, begin implementing Article 21 controls. That advice is incomplete — and for universities, it may lead your institution to the wrong conclusion entirely.

The NIS2 Directive (EU) 2022/2555 lists research in Annex II, its register of “other critical sectors.” But the Annex II definition of research organisations contains an explicit clause that most compliance guides do not mention: it excludes higher education institutions from the research sector classification [6]. A university is not automatically an Annex II research organisation, regardless of how much research it conducts.

That does not mean universities are outside NIS2 entirely. It means they enter scope through a different legal provision — Article 2(5)(b) — which operates on Member State discretion and a qualifying condition the directive leaves undefined [1]. Understanding which track your institution is on determines whether your obligations are immediate and automatic, or conditional on national legislation, your registration deadline, and what your governing body is required to approve.

This article maps both tracks, gives a structured decision framework for each, and outlines what compliance looks like once you are in scope.

Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

The Research Sector’s Place in NIS2 — and Why the Standard Guidance Misses a Critical Detail

NIS2 organises covered sectors into two annexes. Annex I covers high-criticality sectors: energy, transport, banking, health, digital infrastructure, drinking water, wastewater, and public administration. Annex II covers “other critical sectors” — industries whose disruption would be significant but whose immediate or cross-border impact is assessed as less severe than Annex I. Research appears in Annex II.

Entities in Annex I that exceed medium-enterprise size thresholds are classified as Essential Entities under Article 3(1) and face proactive, ongoing supervision by national competent authorities [2]. Entities in Annex II that meet the same size criteria become Important Entities under Article 3(2) and face reactive supervision — regulators act primarily in response to reported incidents rather than through standing audit programmes. Both categories carry the same core obligations under Articles 21 and 23, but the supervisory intensity differs significantly. For a comparison of how these classifications work in practice, see our guide on essential versus important entities.

The size threshold is set by EU Recommendation 2003/361/EC, referenced in Article 2(1): a medium-sized enterprise has 50 or more employees, or annual turnover or balance sheet total exceeding €10 million. Meeting either criterion is sufficient. Organisations below both thresholds are generally out of scope unless they are the sole provider of a critical national service.

Here is where the standard guidance typically stops — sector plus size equals obligation. But that conclusion skips over the definition of what constitutes a “research organisation” under Annex II, and that definition is the entire scope question for universities and public research institutions.

Two Legal Tracks: Why Your Institution Type Determines Everything

The NIS2 Directive creates two separate legal pathways for research-related entities. Which track applies to your institution is determined by its primary purpose and legal form, not by research volume or headcount alone.

Track 1 — Annex II: Research Organisations. Annex II defines research organisations as entities whose primary goal is to carry out applied research or experimental development with a view to exploiting results for commercial purposes — explicitly excluding higher education institutions [6]. If your organisation meets this definition and clears the size threshold, it is an Important Entity under Article 3(2). Inclusion is automatic. No Member State act is required.

Track 2 — Article 2(5)(b): Education Institutions with Critical Research Activities. Article 2(5)(b) provides that Member States may apply the directive to education institutions, “in particular where they carry out critical research activities” [1]. This is a discretionary provision — Member States are not obligated to include universities. Whether your university falls under NIS2 depends on whether your national government has exercised this option in its transposition legislation, and whether your institution qualifies under the “critical research” qualifier.

The practical consequence: two research-intensive institutions in the same EU city — one a private contract research organisation with 60 scientists, one a university faculty of 400 researchers — may face radically different NIS2 obligations depending purely on their legal form and their Member State’s implementation choices.

Entity Type NIS2 Track Automatic Inclusion?
Private research company / CRO (50+ staff or €10M+ turnover) Track 1: Annex II — Research organisations Yes
State-funded institute with commercial research mandate (50+ staff) Track 1: Annex II — Research organisations Yes
University / higher education institution Track 2: Article 2(5)(b) — Discretionary Member State dependent
University spinout / technology transfer company Track 1 (if primary purpose is commercial R&D and size threshold met) Yes, if both criteria met
Small research firm (<50 staff and <€10M turnover) Neither (size exemption applies) No, unless sole critical provider

Track 1 — Commercial Research Organisations Under Annex II

For entities that qualify as research organisations under Annex II, NIS2 in-scope status rests on two checks: primary purpose and size. Both must be satisfied.

The primary purpose test. The Annex II research sector definition turns on the organisation’s goal: applying research toward commercial exploitation [6]. This covers contract research organisations (CROs) conducting studies for pharmaceutical or technology clients, independent research institutes with technology transfer and licensing mandates, public research foundations structured to produce commercially applicable outputs, and R&D subsidiaries of larger corporate groups. The common thread is that the entity’s core activity is producing marketable results from research, not teaching.

What the Annex II research category does not cover: teaching-primary universities, academic departments whose research output is primarily published rather than commercialised, and basic science institutes without commercial development objectives. These entities are categorically excluded from the Annex II research organisation definition and must seek scope determination through Track 2.

The size check. Meeting the medium-enterprise threshold requires 50 or more employees, or annual turnover or balance sheet total exceeding €10 million. Either criterion triggers scope independently. Below both thresholds, the size exemption applies unless the organisation is the sole provider of a service of critical national importance [7].

Corporate group consolidation. Research subsidiaries of larger corporate groups cannot treat themselves as stand-alone micro-enterprises for threshold purposes. Under the EU’s enterprise linkage rules (Annex to Recommendation 2003/361/EC), linked and partner enterprises aggregate their staff and financial figures. A 30-person CRO wholly owned by a €500 million pharmaceutical group is not below the size threshold for NIS2 purposes.

Classification outcome. Track 1 entities are Important Entities under Article 3(2), not Essential Entities. This means reactive, ex-post supervision: your competent authority does not routinely inspect you, but conducts investigation and enforcement if a significant incident is reported or a complaint is received. The obligations themselves — Article 21 risk management, Article 23 incident reporting — are the same regardless of supervision model.

Track 2 — Universities and the Article 2(5)(b) Discretionary Door

Universities occupy an unusual position under NIS2. They are explicitly excluded from the Annex II research organisation definition, yet Article 2(5)(b) creates a route for Member States to bring them into scope. Two conditions must both be satisfied: the Member State must exercise the discretion in its national transposition legislation, and the university must carry out “critical research activities” [1].

The Member State condition. This is a legislative act. If a Member State has not explicitly included education institutions in its NIS2 transposition law, universities in that country have no NIS2 obligation under this provision — regardless of research volume, EU funding received, or institutional size. As of mid-2026, several major EU economies have not finalised their transposition, meaning the position of universities remains legally unresolved in those jurisdictions.

The critical research activities condition. The directive specifies “in particular where they carry out critical research activities” but does not define that phrase. Member States and their competent authorities are left to interpret it. Based on the directive’s overall framework and context, reasonable indicators of critical research activities include: research with dual-use technology applications under Regulation (EU) 2021/821; projects within Horizon Europe’s Cluster 3 (Civil Security for Society); research that directly supports services in Annex I sectors such as energy or health; defence-related research funded by defence ministries or the European Defence Fund; and large-scale genomic, biomedical, or health security research processing sensitive personal data.

These are indicators based on regulatory context and logical interpretation, not a formally adopted list. Member States retain discretion to draw the line differently. If your university undertakes research in any of the categories above, the responsible position is to treat the possibility of in-scope classification seriously and seek guidance from your national competent authority.

The hybrid institution problem. Some universities operate both a teaching faculty and a separately managed commercial research arm — sometimes as a distinct legal entity. If that commercial arm has its own legal personality, a primary commercial research mandate, and meets the size threshold, it may independently qualify as a Track 1 research organisation under Annex II, entirely separately from the parent university’s Track 2 exposure. Legal structure matters: two entities operating under the same university brand may face two different NIS2 tracks simultaneously.

Does NIS2 Apply to Your Institution? A Decision Framework

Apply these questions in order. The first “No” that cannot be overcome ends the analysis for that track.

Track 1 Check (Research Organisations)

Q1: Is your entity’s primary purpose commercial applied research? If the organisation exists primarily to teach students and advance academic knowledge, with research as a secondary or co-equal activity, this test fails. If the primary mandate is to produce commercially exploitable research outputs — CRO work, licensing, technology transfer, industrial partnerships — this test passes.

Q2: Do you have 50+ employees or €10M+ annual turnover? Check both thresholds independently. If operating within a larger corporate group, apply the linkage rules before answering.

If both Q1 and Q2 are Yes: you are a Track 1 Important Entity. Registration with your national competent authority and Article 21 compliance are required.

Track 2 Check (Universities and Education Institutions)

Q3: Has your Member State’s NIS2 transposition law included education institutions? This requires reading the actual national legislation, not EU-level summaries. Look for explicit reference to “education institutions,” “universities,” or “higher education” in the transposition text. For a current overview of which countries have transposed and how, the NIS2 scope guide tracks national implementation status.

Q4: Does your institution conduct critical research activities? Apply the indicators in the previous section: dual-use research, Horizon Europe Cluster 3 participation, Annex I sector-support research, defence contracts, or large-scale sensitive data processing. Multiple indicators present = material in-scope risk.

Q5: Have you notified your national authority under Article 3(3)? By April 17, 2025, Member States were required to establish lists of essential and important entities, and entities meeting the criteria were required to submit identifying information [2]. If your institution is in scope and has not notified, this is an active compliance gap.

If Q3 and Q4 are both Yes: you are a Track 2 entity subject to your Member State’s national NIS2 implementation. The core obligations — Article 21 risk management, Article 23 incident reporting — will be defined by that national law.

Member State Variation — Why Your Country Determines Your Exposure

The two-track structure means university NIS2 exposure is primarily a national law question, not a uniform EU-level rule. Implementation varies substantially.

Italy has been the most expansive. Italy’s NIS2 transposition (Legislative Decree No. 138/2024) explicitly included research institutions among additional covered entity types, alongside cultural organisations and local public transport operators. Italian universities conducting critical research are among the most clearly in-scope across the EU [10].

Germany combines NIS2 with its broader KRITIS-DachG (“critical infrastructure umbrella law”) framework, which entered into force in 2024 and expands critical infrastructure definitions. However, the specific treatment of universities under the complete NIS2 transposition remains under development as of mid-2026. German institutions should monitor BSI guidance for sector-specific clarification rather than assuming either inclusion or exclusion.

Belgium has broadened its NIS2 scope beyond the directive minimum in several areas, with the Centre for Cybersecurity Belgium (CCB) as the designated competent authority. The specific treatment of Belgian universities in the transposition text has not been conclusively settled; Belgian research institutions should consult CCB directly.

Most other Member States have not yet issued specific guidance on university inclusion. Where transposition is incomplete or silent on education institutions, universities face no current enforcement exposure for Track 2 obligations — but that position will change as transpositions finalise. Preparing compliance infrastructure now means the answer to final enforcement does not depend on a rushed implementation timeline.

Multi-country consortia. In Horizon Europe projects, each consortium partner must assess its NIS2 position under its own Member State’s law. A partner institution that is clearly in scope in Italy may have no formal obligation under current Spanish implementation. This creates asymmetric compliance burden across legally integrated research projects, which consortium agreements should address explicitly.

When You Are In Scope — Important Entity Obligations

Once your institution is confirmed in scope — whether via Track 1 or Track 2 — the obligations that apply are those for Important Entities under the NIS2 Directive. The following table summarises the primary requirements and their enforcement parameters.

Obligation Source Key Requirement
Cybersecurity risk management Article 21 Implement 10 security domains: risk policies, incident handling, BCP, supply chain, network security, effectiveness review, training, cryptography, HR/access control, MFA
Incident reporting Article 23 Early warning within 24 hours; initial notification with severity assessment within 72 hours; final report within 1 month
Entity registration Article 3(3) Notify national competent authority (name, address, sector, contact, services); deadline was 17 April 2025
Management accountability Article 20 Governing body approves and oversees cybersecurity measures; management undergoes training; personal liability for infringements applies
Effectiveness review Article 21(2)(f) Periodic review and documentation of cybersecurity measures; results available for audit

Penalty exposure. Article 34 sets the maximum administrative fine for Important Entities at the higher of €7,000,000 or 1.4% of total worldwide annual turnover in the preceding financial year [3]. Fines must be “effective, proportionate and dissuasive” and are determined alongside corrective measures. Member States may also impose periodic penalty payments to compel compliance after an enforcement decision.

Management liability. Article 20 is frequently underestimated in research environments. It requires the governing body — the rector, president, or board of trustees, depending on institutional structure — to approve cybersecurity risk management measures and to complete cybersecurity training. For many universities, this represents a materially new governance obligation that existing information security committees are not structured to discharge. For a detailed treatment of what boards must do and document, see our guide to board responsibilities under NIS2.

Supervision model. The reactive ex-post model means regulators do not routinely inspect Important Entities. This can create a misleading sense of low urgency. In practice, a significant cybersecurity incident at a research institution — a ransomware attack disrupting clinical trials, a state-sponsored intrusion exfiltrating pre-publication data — will trigger an ex-post investigation in which auditors will examine whether Article 21 controls were in place before the incident. Institutions that have not implemented compliance infrastructure will face both enforcement and reputational damage simultaneously.

Research-Specific Compliance Priorities Under Article 21

Not all ten Article 21(2) domains carry equal risk for research institutions. The research sector’s threat profile is distinctive: intellectual property theft, state-sponsored espionage, and highly connected collaborative networks create specific vulnerabilities that generic compliance frameworks do not address directly [9].

Access control and asset management (Article 21(2)(i)) — lead priority. Research institutions generate and store some of the most valuable data in the European economy: pre-publication findings, proprietary experimental methods, biomedical datasets with regulatory significance, and dual-use technical data. Every research dataset and IP-sensitive system should be classified, with access restricted to project-specific personnel. Academic cultures that default to open sharing create friction here — implementing least-privilege access for research data requires both technical controls and cultural change.

Supply chain security (Article 21(2)(d)) — the collaboration risk. Academic collaboration is NIS2’s supply chain security obligation in research disguise. When a university joins a Horizon Europe consortium, each partner institution’s network becomes an access pathway into all others. Article 21(2)(d) requires documented assessment of “security-related aspects concerning the relationships between each entity and its direct suppliers or service providers” [4]. Consortium participation agreements and researcher exchange MoUs should include cybersecurity clauses — a provision most academic agreements currently lack.

Incident handling and reporting (Articles 21(2)(b) and 23) — the 24-hour challenge. The early warning requirement runs from the moment your organisation becomes aware of a significant incident — not from when IT formally investigates. Most research institutions lack a CSIRT (Computer Security Incident Response Team) that operates outside business hours. Ransomware attacks against research networks routinely begin late Friday evenings. Building a response capability that can meet the 24-hour clock requires documented procedures, out-of-hours contacts, and tested escalation paths, not just policy documents [8].

Cybersecurity training (Article 21(2)(g)) — the culture gap. Research environments prioritise openness, device flexibility, and frictionless data exchange — behaviours that create security risk. Training programmes for research institutions need to address the specific practices that generate incidents in academic settings: personal devices on research networks, unrestricted external data sharing, and resistance to multi-factor authentication in high-throughput laboratory settings.

Role Key NIS2 Responsibilities
Rector / President / Vice-Chancellor Approve cybersecurity risk management policy; complete cybersecurity training; personal accountability under Article 20
CISO / IT Security Lead Implement Article 21 controls; maintain incident response capability; manage Article 23 reporting chain
Research Director / PI IP classification for research data; supply chain security for collaborative projects and consortium agreements
Legal / Compliance Officer NCA registration obligation; Article 23 reporting chain documentation; audit-readiness evidence management
Board / Supervisory Council Governance sign-off under Article 20; training completion; policy approval documentation

Frequently Asked Questions

Our university has 5,000 staff and €500 million in annual budget. Is it automatically in scope?

Not automatically. Size thresholds alone do not place a university in scope. Universities are excluded from the Annex II research organisation definition, so in-scope status depends on whether your Member State has included education institutions under Article 2(5)(b) and whether your institution conducts critical research activities. Verify your national transposition legislation before assuming either conclusion.

We are a public research institute funded by government grants. Are we in scope?

Potentially yes under Track 1, if your institute’s primary purpose is applied research with commercial exploitation objectives — technology transfer, licensing, or industry-funded projects. Many public research institutes operate under a commercial mandate that qualifies as a Track 1 research organisation regardless of public ownership. Check your founding statute and primary mission statement.

We have a university spinout conducting contract research for industry. Is the spinout in scope?

Very likely yes. A separate legal entity with a primary purpose of applied commercial research qualifies as a Track 1 research organisation under Annex II, subject to the size threshold. The parent university’s excluded status does not extend to subsidiaries with different primary mandates.

What is the difference in practice between Track 1 and Track 2 compliance obligations?

The underlying Article 21 and Article 23 obligations are the same for both tracks. The difference is the legal basis for inclusion, which regulatory authority supervises you, and — in some Member States — which national rules supplement the directive. Track 1 entities are in scope under EU law directly; Track 2 entities are in scope under national implementing legislation, which may add requirements beyond the directive minimum.

We participate in Horizon Europe security research projects. Does that make us automatically in scope?

Participation in Horizon Europe Cluster 3 security projects is a material indicator of critical research activities for Article 2(5)(b) purposes, but it does not automatically place a university in scope. The Member State must first have included education institutions in its transposition. Horizon Europe participation is a reason to verify your national law and seek authority guidance — not itself a definitive trigger.


This article provides general information only and does not constitute legal or regulatory advice. Requirements may vary by jurisdiction and organisation type. Consult a qualified legal professional or compliance specialist for advice specific to your situation.

Sources

  1. European Commission, “NIS 2 Directive Article 2 — Scope,” nis-2-directive.com — https://www.nis-2-directive.com/NIS_2_Directive_Article_2.html
  2. European Commission, “NIS 2 Directive Article 3 — Essential and Important Entities,” nis-2-directive.com — https://www.nis-2-directive.com/NIS_2_Directive_Article_3.html
  3. European Commission, “NIS 2 Directive Article 34 — Administrative Fines for Important Entities,” nis-2-directive.com — https://www.nis-2-directive.com/NIS_2_Directive_Article_34.html
  4. European Commission, “NIS 2 Directive Article 21 — Cybersecurity Risk-Management Measures,” nis-2-directive.com — https://www.nis-2-directive.com/NIS_2_Directive_Article_21.html
  5. StreamLex, “NIS2 Directive — Annex II,” streamlex.eu — https://streamlex.eu/annexes/nis2-en-annex-ii/
  6. Legiscope, “NIS2 Essential vs Important Entities Explained,” legiscope.com — https://www.legiscope.com/blog/nis2-essential-important-entities.html
  7. Enactia, “NIS2 Essential vs Important Entities: Scope Decision Guide,” enactia.com — https://enactia.com/nis2-essential-vs-important-entities-scope-decision-guide/
  8. ISMS.online, “NIS 2 for Research: Who’s In Scope, What Changes, and Why Evidence Matters,” isms.online — https://www.isms.online/nis-2/sectors/research/requirements/
  9. NIS2Directive.eu, “Research Sector Implications,” nis2directive.eu — https://nis2directive.eu/research/
Free Download

Get the NIS2 Article 21 Compliance Checklist

90+ assessment items mapped to CIR 2024/2690 — instant PDF, no payment.

✓ Check your inbox — the PDF is on its way.

Don't miss: